Implement HIPAA Security Rule Administrative Safeguards for incident response + contingency + evaluation. Security Incident Procedures per 45 CFR 164.308(a)(6): identify and respond to suspected or known security incidents + mitigate harmful effects + document incidents and outcomes. Contingency Plan per 45 CFR 164.308(a)(7): Data Backup Plan (Required) + Disaster Recovery Plan (Required) + Emergency Mode Operation Plan (Required) + Testing and Revision Procedures (Addressable) + Applications and Data Criticality Analysis (Addressable). Evaluation per 45 CFR 164.308(a)(8): perform periodic technical and non-technical evaluation initially based on the standards and subsequently in response to environmental or operational changes affecting the security of ePHI. Apply NIST SP 800-61 IR methodology and NIST SP 800-34 contingency planning methodology + integrate with HIPAA Breach Notification Rule (45 CFR 164.400-414) for any breach affecting ePHI.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.